Description
yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared Redis keys controlling customer auto-recycling behavior, causing mass customer data deletion, disabling lead recycling, or blocking customer creation across the deployment.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation and data loss
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the yshop‑crm application, where the saveRedisSet and getRedisSet endpoints in CrmCustomerController do not enforce authorization checks. This allows any authenticated back‑office user to read and modify shared Redis keys that control the system’s customer auto‑recycling policy and lead‑allocation behaviour. An attacker could, therefore, trigger mass deletion of customer records, disable lead recycling, or prevent new customer creation, resulting in significant integrity and availability damage.

Affected Systems

The affected product is yshop‑crm from the vendor guchengwuyue. All releases up to and including version 2.1.3 are vulnerable. No newer versions are listed as affected.

Risk and Exploitability

The CVSS score of 7.1 marks this as a high‑severity flaw. The EPSS score of less than 1% indicates a very low exploitation probability at the time of assessment, and the vulnerability is not listed in CISA KEV. The likely attack vector, inferred from the description, is an authenticated back‑office user executing the exposed endpoints without additional authorization. Successful exploitation would give the attacker the ability to manipulate critical business-configurable Redis keys, leading to destructive data loss or operational disruption.

Generated by OpenCVE AI on September 18, 2026 at 06:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade yshop‑crm to a version newer than 2.1.3 to restore proper authorization on the affected endpoints.
  • Configure the application’s access control to require an administrative role for the saveRedisSet and getRedisSet endpoints, ensuring only privileged users can modify the auto‑recycling policy.
  • Add safeguards to the Redis instance, such as ACL rules or keyspace notifications, to detect and prevent unauthorized changes to the auto‑recycling keys.
  • Monitor application logs for unexpected usage of the saveRedisSet and getRedisSet endpoints and investigate any anomalies promptly.

Generated by OpenCVE AI on September 18, 2026 at 06:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Guchengwuyue
Guchengwuyue yshop-crm
Vendors & Products Guchengwuyue
Guchengwuyue yshop-crm

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared Redis keys controlling customer auto-recycling behavior, causing mass customer data deletion, disabling lead recycling, or blocking customer creation across the deployment.
Title yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Guchengwuyue Yshop-crm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T13:27:23.763Z

Reserved: 2026-09-16T10:40:54.112Z

Link: CVE-2026-92456

cve-icon Vulnrichment

Updated: 2026-09-16T13:27:09.641Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T12:17:06.900

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-92456

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses